Microsoft

Principal Security Research Manager, Applied Threat Intel & Threat Response - Microsoft Security

Microsoft$142K — $274K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Doctorate or equivalent experience with 3+ years in cybersecurity, threat analysis, or related fields.
  • Master's or Bachelor’s degree with extensive experience in threat modeling or vulnerability research.
  • Minimum of 1 year in people management, driving team performance and culture.
  • Demonstrated ability producing finished threat intelligence for various audiences.
  • Experience with Microsoft Sentinel and Defender XDR or comparable platforms.

Responsibilities

  • Lead recruitment and development of a high-performing threat intelligence and response team.
  • Set goals aligning team tasks with business objectives and adjust as necessary based on threat landscape changes.
  • Cultivate a culture of excellence and continuous learning within the team.
  • Oversee production of impactful threat intelligence outputs, ensuring high standards and quality.
  • Ensure readiness and training for threat response team for rapid incident engagement.
  • Develop relationships across the intelligence community to enhance organizational strategies and responses.
  • Define vision and strategy for delivering high-quality intelligence and threat responses.

Benefits

  • Comprehensive health coverage, including medical, dental, and vision.
  • Generous paid time off allowance, including vacation and holidays.
  • Opportunities for professional development and career advancement.
  • Flexible work arrangements, including remote options.
  • Retirement savings plan with company matching contributions.
Full Job Description
Overview

Microsoft Security Research is at the front line of defending Microsoft customers and the broader ecosystem against the world's most sophisticated threat actors. Our Applied Threat Intelligence and Threat Response team serves two complementary missions: producing finished, customer-ready threat intelligence that empowers defenders and shapes the public narrative on the threat landscape - and responding with speed and precision when adversaries act against Microsoft customers and infrastructure in this new AI era.

We are looking for a Principal Security Research Manager to lead this blended team. Your threat intelligence analysts are writers and producers: they author actor profiles, campaign analyses, TTP deep-dives, and vulnerability profiles that ship through Microsoft's customer-facing surfaces and brief C-suite audiences. Your threat response practitioners are operators: they maintain on-call readiness, lead active incident investigations, and close the loop from response findings back into finished intelligence. You own both missions, the talent that executes them, and the standards that make the work credible and impactful.

Responsibilities

People Leadership
  • Recruit, develop, and retain a high-performing blended team spanning two distinct but complementary disciplines: finished intelligence production and threat response operations.
  • Set clear goals for each function, connect individual work to team and business objectives, and adapt priorities as the threat landscape and organizational needs evolve.
  • Foster a culture of analytic rigor, operational excellence, and continuous learning - modeling Microsoft values and driving team culture improvements daily.
  • Mentor analysts and responders on tradecraft, career development, and the standards that define great intelligence and response work.

Finished Intelligence Production
  • Own the team's customer-ready intelligence output - actor profiles, campaign analyses, TTP deep-dives, vulnerability profiles, and trend reports - with accountability for quality, cadence, and real-world impact.
  • Establish and maintain analytic standards, tradecraft guidance, and peer review practices that ensure your team's finished intelligence is credible, prescriptive, and audience-appropriate from SOC analyst to C-suite.
  • Partner with product, research, marketing, and communications teams to land intelligence through Microsoft's customer-facing surfaces (Defender XDR, Sentinel, Agentic Security, blogs, executive briefings).

Threat Response Operations
  • Ensure threat response practitioners are trained, calibrated, and ready for on-call rotation and rapid-response engagements.
  • Hold the team accountable for quality monitoring, root cause analysis, and post-incident process improvements.
  • Drive the closed loop between response and intelligence: response findings feed directly into finished intelligence products and detection improvements, making the next response faster and the next report sharper.

Strategy & Cross-Organizational Influence
  • Develop trusted relationships across the intelligence community, including industry partners, external organizations, and agencies engaged in tracking criminal threat actors.
  • Define the vision, strategy, and priorities for the team to deliver high-quality intelligence and threat response that drives customer protection and business impact.
  • Build and operationalize a hybrid human + agentic intelligence team, applying AI technologies, automation, and workflow innovation to improve scale, speed, and insight generation.


Qualifications

Minimum Qualifications:
• Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
• OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
• OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
• OR equivalent experience.
• 1+ year(s) people management experience.

Other Requirements:
Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:
Microsoft Cloud Background Check:
• This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.
• This position requires verification of U.S. citizenship due to citizenship-based legal restrictions. Specifically, this position supports United States federal, state, and/or local government agency customers and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, and as a condition of employment, the successful candidate's citizenship will be verified via a valid passport.

Preferred Qualifications:
• Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 5+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
• OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
• OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 12+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection.
• OR equivalent experience.
• 3+ years people management and/or informal/indirect team leadership experience.
• Demonstrated experience producing or overseeing finished threat intelligence reporting for technical and/or executive audiences.
• Working experience with Microsoft Sentinel and Microsoft Defender XDR (or directly comparable SIEM/XDR platforms).
• 10+ years of experience in cyber threat intelligence, threat hunting, incident response, or a closely related security discipline.
• Demonstrated track record leading a finished intelligence production function - owning report quality, publication standards, and the analytic tradecraft that makes intelligence credible and actionable.
• Experience managing or operating across both intelligence production and incident response disciplines, with fluency in the tension between long-horizon analysis and rapid-response demand.
• Portfolio of public or customer-facing intelligence writing (actor profiles, campaign reports, vulnerability analyses, or equivalent).
• Understanding of adversary tradecraft and frameworks including MITRE ATT&CK, the Diamond Model, Cyber Kill Chain, and structured analytic techniques.
• Experience with endpoint, cloud, network, and identity-based attacks and datasets.
• Programming or scripting background (Python, KQL, PowerShell, or equivalent) sufficient to evaluate and guide technical work on the team.
• Familiarity with AI-assisted intelligence workflows and automation approaches for threat triage, enrichment, and intelligence delivery at scale.

#MSSecurity

Security Research M5 - The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay

This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.

About Microsoft

Microsoft is an American multinational corporation that develops, manufactures, licenses, supports, and sells a range of software products and services. Microsoft’s devices and consumer (D&C) licensing segment licenses the Windows operating system and related software, Microsoft Office for consumers, and the Windows Phone operating system. The company’s computing and gaming hardware segment provides Xbox gaming and entertainment consoles and accessories, second-party and third-party video games, and Xbox Live subscriptions; surface devices and accessories; and Microsoft PC accessories. Its phone hardware segment offers Lumia smartphones and other non-Lumia phones. Its D&C segment provides Windows Store, Xbox Live transactions, and Windows phone store; search advertising; display advertising; Office 365 Home and Office 365 Personal; first-party video games; and other consumer products and services as well as operating retail stores. Microsoft’s commercial licensing segments license server products, including Windows Server, Microsoft SQL Server, Visual Studio, System Center, and related Client Access Licenses (CALs); Windows Embedded; Windows operating system; Microsoft Office for business, including Office, Exchange, SharePoint, Lync, and related CALs; Microsoft Dynamics business solutions; and Skype. Its commercial segment offers enterprise services, including premier support services and Microsoft consulting services; commercial cloud comprising Office 365 Commercial, other Microsoft Office online offerings, Dynamics CRM Online, and Microsoft Azure; and other commercial products and online services. The company markets and distributes its products through original equipment manufacturers, distributors, and resellers, as well as online.

Microsoft Careers

Join Microsoft today and be part of a company that values innovation, leadership, and diversity in its workforce. As a global leader in technology and digital transformation, Microsoft offers unparalleled job opportunities that propel your career to new heights.

Explore Career Opportunities at Microsoft

Whether you're a seasoned professional looking for your next challenge or a recent graduate eager to start your career, Microsoft has a position that suits your skills and ambitions. We are committed to fostering a culture of growth and learning, where every team member is supported in expanding their horizons.

Internship Programs

Kickstart your career with a Microsoft internship. Our internships provide invaluable workplace experience and networking opportunities in a supportive and dynamic environment. You'll work on real projects, learn from industry leaders, and gain the skills necessary for a successful career in technology.

Employment Benefits

Choosing a career at Microsoft means more than just a job. Our employees enjoy a range of benefits designed to empower them both professionally and personally. These include comprehensive health benefits, flexible working conditions, and opportunities for career advancement through professional development and diversity training.

Inclusive Culture and Diversity

At Microsoft, we believe that innovation comes from diversity of thought and inclusion. We are committed to a workplace where everyone feels valued and inspired. Our leadership is dedicated to fostering an environment where diverse perspectives lead to breakthrough innovations and a competitive edge.

Grow with Us

Career growth at Microsoft is about more than climbing the corporate ladder; it's about continuous learning, expanding your skills, and improving your capabilities. With access to various leadership and training programs, you can evolve as a professional and make a significant impact within the company and on the global stage.

Hiring Process

Our hiring process is designed to identify true potential. Starting with a review of your resume, followed by interviews that assess your problem-solving abilities and cultural fit, we ensure that all candidates have a fair chance to demonstrate their strengths and potential to contribute to our team.

Networking and Professional Development

Microsoft is a place where you can build a professional network that spans the globe. Our employees benefit from connections with top-tier professionals and industry leaders, which opens doors to innovative projects and collaborative opportunities that are second to none.

Join Our Team

If you're ready to take on exciting challenges and make a difference in the world of technology, explore the job opportunities at Microsoft. Search for open positions that match your skills and interests, and prepare to embark on a rewarding career path filled with innovation and opportunities for personal and professional growth.

Stay Connected

Keep up to date with the latest at Microsoft Careers by subscribing to our job alert emails. Get tailored content that aligns with your career preferences and discover the exciting and rewarding opportunities that await at Microsoft.

SEARCH MICROSOFT JOBS

At Microsoft, your future is limitless. Join us in our mission to empower every person and every organization on the planet to achieve more. Your journey with Microsoft starts here.
Learn more about Microsoft
Size
181,000 employees
Market Cap
$1,762.4 billion
Industry
Net Income
$51.3 billion
Founded
1975
5 Year Trend
+15.5%
Revenue
$153.2 billion
NASDAQ

Similar Jobs

More Jobs at Microsoft

More Information Technology Jobs

Find similar Principal Security Research Manager, Applied Threat Intel & Threat Response - Microsoft Security jobs: